In our inputs there are wildcard entries for directories and I recently noticed there were duplicate entries for the same logfile.
Will that index the logs twice OR does Splunk take care of this and how?
Hi sarnagar,
there isn't any duplications: if you address twice the same file, it will be indexed only one time.
You must take care when you have duplicated inputs if you set different indexes or sourcetypes because the log will be read only one time and assigned only to one index or sourcetype.
Bye.
Giuseppe